Home / Security / Advisories / NTAP-20210611-0006
NTAP-20210611-0006 — April 2021 Eclipse Jetty Vulnerabilities in NetApp Products
Published 2021-06-11 · Updated 2024-05-01 · Status: Final · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: E-Series / SANtricity · Other NetApp products · NetApp Console / BlueXP · ONTAP · SnapCenter | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2021-28163 — LOW · CVSS 2.7 · site index
- CVE-2021-28164 — MEDIUM · CVSS 5.3 · site index
- CVE-2021-28165 — HIGH · CVSS 7.5 · site index
What the CVE records say
CVE-2021-28163 — In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or Denial of Service (DoS).
Affected products
- E-Series SANtricity OS Controller Software 11.x
- E-Series SANtricity Unified Manager and Web Services Proxy
- Element Plug-in for vCenter Server
- NetApp BlueXP
- NetApp E-Series Performance Analyzer
- NetApp SANtricity Cloud Connector
- NetApp VASA Provider for Clustered Data ONTAP 9.7 and above
- ONTAP tools for VMware vSphere 9
- SANtricity Storage Plugin for vCenter
- SnapCenter
- SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine
- Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above
Official fixes
- NetApp BlueXP — vendor fix ↗
- E-Series SANtricity OS Controller Software 11.x — vendor fix ↗
- E-Series SANtricity Unified Manager and Web Services Proxy — vendor fix ↗
- Element Plug-in for vCenter Server — vendor fix ↗
- NetApp E-Series Performance Analyzer — vendor fix ↗
- NetApp VASA Provider for Clustered Data ONTAP 9.7 and above — vendor fix ↗
- SANtricity Storage Plugin for vCenter — vendor fix ↗
- SnapCenter — vendor fix ↗
- SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine — vendor fix ↗
- Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above — vendor fix ↗
- ONTAP tools for VMware vSphere 9 — vendor fix ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2021